Practice for the #2: CC Exam Preparation (100) exam with 20 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of these is NOT a feature of a SIEM (Security Information and Event Management)?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the #2: CC Exam Preparation (100) practice test →
What you will practice
- Which of these is NOT a feature of a SIEM (Security Information and Event Management)?
- Which of these techniques will ensure the property of non-repudiation?
- Which of these enables point-to-point online communication over an untrusted network?
- Which of these is included in an SLA document?
- An organization needs a network security tool that detects and acts in the event of malicious activity. Which…
- Which part of the CIA Triad will be PRIMARILY jeopardized in a Distributed Denial Of Service (DDOS) attack?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Which of these is NOT a feature of a SIEM (Security Information and Event Management)?
Answer: A. Log generation
A Security Information and Event Management system collects, retains, and correlates logs generated by other systems. Log generation is the responsibility of the individual endpoints and network devices, not the SIEM itself.
Q2. Which of these techniques will ensure the property of non-repudiation?
Answer: D. Digital signatures
Digital signatures provide non-repudiation by using the sender's private key to guarantee the message origin. Encryption and virtual private networks primarily provide confidentiality, while passwords only provide authentication.
Q3. Which of these enables point-to-point online communication over an untrusted network?
Answer: C. VPN
A Virtual Private Network creates an encrypted tunnel to secure point-to-point communication across untrusted networks. Routers and firewalls manage traffic, but they do not inherently encrypt the data payload to protect it from eavesdropping.
Q4. Which of these is included in an SLA document?
Answer: D. Instructions on data ownership and destruction
A service level agreement typically includes data ownership and destruction procedures to ensure compliance. Business continuity, disaster recovery, and incident response are separate operational plans that focus on resilience and security strategies rather than vendor service commitments.
Q5. An organization needs a network security tool that detects and acts in the event of malicious activity. Which of these tools will BEST meet their needs?
Answer: D. IPS
An intrusion prevention system monitors network traffic and takes automatic action to block or drop malicious activity. An intrusion detection system only alerts on suspicious traffic, while a firewall strictly enforces predetermined rule sets without deep packet inspection.
Q6. Which part of the CIA Triad will be PRIMARILY jeopardized in a Distributed Denial Of Service (DDOS) attack?
Answer: B. Availability
Distributed denial of service attacks primarily jeopardize availability by overwhelming a target with malicious traffic until it collapses. Confidentiality and integrity are usually not the direct targets of this specific attack method.
Q7. Which of these cloud deployment models is a combination of public and private cloud storage?
Answer: A. Hybrid
A hybrid cloud deployment model combines public and private cloud storage to meet specific organizational needs. Public models share infrastructure openly, whereas private models restrict access to a single organization.
Q8. What is the PRIMARY objective of a rollback in the context of the change management process?
Answer: B. Restore the system to its last state before the change was made
The primary objective of a rollback during change management is to restore a system to its previous known good state. This helps resolve unexpected issues quickly if a deployment fails or causes unintended network disruptions.
Q9. Which cloud service model provides the most suitable environment for customers who want to install their custom operating system?
Answer: D. IaaS
Infrastructure as a Service is the most suitable cloud model for customers needing custom operating systems because it provides deep control over virtualized resources. Software and Platform as a Service models limit user access to the underlying operating system layer.
Q10. Which of these is an attack that encrypts the organization's information, and then demands payment for the decryption code?
Answer: B. Ransomware
Ransomware is an attack that encrypts an organization's information and demands payment for the decryption key. The other options represent different attacks, such as denial of service or social engineering, which do not typically involve encrypting data for ransom.
Q11. Which of these techniques is PRIMARILY used to ensure data integrity?
Answer: B. Message Digest
Message digesting uses cryptographic hash functions to ensure data integrity by detecting any unauthorized changes to the data. Content encryption primarily provides confidentiality, backups offer recovery, and labeling is used for data classification.
Q12. An IT company is planning a new data analytics project that would provide enhanced tracking capabilities, but it conflicts with data protection principles. Senior management pressures the Data Protection Officer (DPO) to approve the projec…
Answer: B. Provide independent advice based on data protection law
A Data Protection Officer must act independently and provide expert advice based on data protection law rather than business objectives. The officer advises on legal risks but does not have the authority to approve or deny projects, making the other options violations of independence.
Q13. Which of these devices has the PRIMARY objective of determining the most efficient path for the traffic to flow across networks?
Answer: D. Routers
A router operates at layer three and determines the most efficient path for traffic to flow across networks. Switches and hubs operate within a local network to connect devices, while firewalls are designed primarily to block unauthorized traffic based on security rules.
Q14. In an incident response process, which phase uses indicators of compromise and log analysis as part of a review of events?
Answer: B. Identification
The identification phase of incident response uses indicators of compromise and log analysis to detect and validate that a security incident has occurred. Preparation involves getting ready beforehand, while containment and eradication handle limiting and removing the threat after identification.
Q15. Which kind of document outlines the procedures ensuring that vital company systems keep running during business-disrupting events?
Answer: C. Business Continuity Plan
A Business Continuity Plan outlines the procedures to sustain critical business operations during and after a disruptive event. A Disaster Recovery Plan focuses on restoring IT infrastructure, while a Business Impact Analysis assesses the potential effects of an outage.
Q16. In the event of non-compliance, which of these can have considerable financial consequences for an organization?
Answer: B. Regulations
Regulations are legal requirements established by government bodies, and failing to comply with them can result in severe financial penalties. Standards are usually voluntary, guidelines are advisory, and policies are internal rules that lead to disciplinary rather than legal action.
Q17. An organization that uses a layered approach when designing its security architecture is using which of these security approaches?
Answer: D. Defense in depth
Defense in depth is a security strategy that uses multiple layers of controls to protect assets. If one layer fails, others remain to stop the threat. Zero trust, network access control, and network layers describe different concepts and do not define this layered architectural approach.
Q18. Which of these is a type of corrective security control?
Answer: D. Patches
Patches are corrective controls because they fix vulnerabilities after an issue is discovered. Encryption acts as a preventive control, intrusion detection systems are detective controls, and guidelines are administrative controls that direct behavior.
Q19. Which kind of physical access control is LESS effective at preventing unauthorized individual access to a data center?
Answer: A. Bollards
Bollards are physical barriers designed to stop vehicles, making them ineffective at preventing individual pedestrian access to a data center. Turnstiles, fences, and standard barriers actively restrict or slow down people trying to enter a facility.
Q20. The name, age, location and job title of a person are all examples of:
Answer: A. Attributes
Attributes are specific pieces of descriptive data about a user, such as their name, age, location, or job title. Identity and biometric factors are used strictly for verification, while account permissions determine what a user can access.
More #2: CC Exam Preparation (100) drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.